A coordinated international law enforcement operation has dismantled the core infrastructure behind Kratos, a widely used phishing-as-a-service (PhaaS) platform that enabled criminals to steal active Microsoft 365 session tokens and bypass multi-factor authentication. Authorities seized approximately 200 Kratos servers as part of the operation, and investigators estimate the platform facilitated around 15,000 phishing campaigns per month. The takedown also led to the arrest of the tool's alleged developer in Indonesia.

German and US authorities announced the takedown on Monday, with the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA) leading the effort. German investigators described Kratos as one of the most widely deployed criminal phishing kits in the world.

The Dangerous Evolution Beyond Credential Theft

Kratos represented a significant evolution in phishing attacks. Its primary capability was not to steal simple usernames and passwords, but to intercept active session tokens during the login process. This technique, known as an adversary-in-the-middle (AiTM) attack, allows criminals to hijack an authenticated session directly.

Session tokens are what applications use to verify a logged-in user. By stealing these tokens, attackers gain persistent access to a compromised account for the lifetime of the token, rendering standard MFA protections ineffective. This made Kratos a potent threat for organizations using Microsoft 365, where one stolen session could expose email, files, and an entire suite of connected services.

The platform operated on a PhaaS model, providing subscribers with ready-made phishing infrastructure and harvesters in exchange for a fee. This lowered the barrier to entry, allowing less technically skilled criminals to launch sophisticated session-hijacking campaigns.

A Strategic Strike on the PhaaS Supply Chain

The operation targeted the PhaaS platform itself, a strategic move aimed at disrupting the criminal ecosystem at its source. Rather than chasing individual phishing campaigns, authorities crippled the underlying service that enabled numerous threat actors to operate.

PhaaS platforms like Kratos have proliferated by offering subscription-based access to attack infrastructure, effectively industrializing phishing. By taking down the central tool, law enforcement aimed to cause a broader impact across multiple criminal networks that relied on it.

The cross-border cooperation between German, US, and Indonesian agencies highlights a growing emphasis on dismantling cybercrime infrastructure through coordinated international action.

MFA is Not a Silver Bullet

The Kratos case starkly demonstrates that while multi-factor authentication is essential, it is not impervious to modern attack techniques. The incident reinforces the need for layered, robust security controls beyond basic MFA.

Security experts recommend organizations implement stricter session lifetime policies to limit the window of opportunity for stolen tokens. Additional defenses include conditional access policies that assess device health and login context, as well as advanced anomaly detection systems to spot unusual sign-in behavior.

User training remains critical. Attacks using AiTM kits typically start with a convincing phishing lure—like a shared document link or a password expiry notice—designed to guide victims through a realistic login proxy.

The arrest of the alleged developer and seizure of Kratos's infrastructure mark a major operational success. However, the underlying demand for session-stealing phishing tools ensures that successor platforms will likely emerge, continuing the cat-and-mouse game between defenders and cybercriminals.


國際聯合執法行動瓦解了廣泛使用的釣魚即服務平台 Kratos 的核心基礎設施。該平台曾被犯罪分子用作竊取活躍的 Microsoft 365 會話令牌並繞過多因素驗證。當局在行動中扣押了約 200 台 Kratos 伺服器,調查人員估計該平台每月促成約 15,000 宗釣魚攻擊。此次行動亦導致涉嫌開發者在印尼被捕。

德國及美國當局於周一宣佈破獲此案,行動由法蘭克福檢察院網絡犯罪部門與德國聯邦刑事警察局主導。德國調查人員指 Kratos 是全球部署範圍最廣的犯罪釣魚工具包之一。

超越憑證竊取的危險演進

Kratos 代表了釣魚攻擊的重大演進。其主要功能並非竊取簡單的用戶名和密碼,而是在登入過程中攔截活躍的會話令牌。這種被稱為中間人攻擊的技術,使犯罪分子能夠直接劫持已驗證的會話。

會話令牌是應用程式用於驗證已登入用戶的憑證。通過竊取這些令牌,攻擊者能在令牌有效期內持續訪問被入侵帳戶,使標準多因素驗證防護失效。這使 Kratos 成為使用 Microsoft 365 的企業組織面臨的嚴重威脅——單個被竊的會話可能暴露電子郵件、檔案及整套互聯服務。

該平台採用釣魚即服務模式營運,向訂閱者提供即用型釣魚基礎設施和數據收割工具以換取費用。此舉降低了技術門檻,使技術能力較弱的犯罪分子也能發動精密的會話劫持行動。

針對釣魚即服務供應鏈的戰略打擊

此次行動直接針對釣魚即服務平台本身,旨在從源頭破壞犯罪生態系統。執法部門並未追查個別釣魚攻擊,而是癱瘓了支撐眾多威脅分子運作的基礎服務。

像 Kratos 這樣的釣魚即服務平台通過提供訂閱制攻擊基礎設施而迅速蔓延,實質上實現了釣魚攻擊的工業化。通過摧毀核心工具,執法部門意圖對依賴該平台的多個犯罪網絡產生廣泛影響。

德國、美國與印尼機構間的跨境合作,凸顯出通過協調國際行動瓦解網絡犯罪基礎設施的策略日益受到重視。

多因素驗證並非萬能盾牌

Kratos 案例清楚表明,雖然多因素驗證至關重要,但無法完全抵禦現代攻擊技術。此事件進一步證實了在基礎多因素驗證之外建立縱深、穩健安全控制的必要性。

安全專家建議組織實施更嚴格的會話生命週期策略,以限制被盜令牌的利用窗口期。其他防護措施包括評估設備健康狀況與登入環境的條件訪問策略,以及能識別異常登入行為的高級異常檢測系統。

用戶培訓仍然至關重要。採用中間人攻擊工具包的攻擊通常始於精心設計的釣魚誘餌(例如共享文件連結或密碼過期通知),引導受害者通過逼真的登入代理伺服器進行操作。

涉嫌開發者被捕及 Kratos 基礎設施被扣押標誌著重大行動成功。然而,市場對竊取會話的釣魚工具持續存在的需求,意味著類似平台很可能繼續出現,攻防雙方的貓鼠遊戲仍將持續。

新聞來源 / Original News Source